Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Privilege Escalation Vulnerability in Cisco SD-WAN Solution
Vulnerability Description
A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate privileges and modify device configuration files. The vulnerability exists because user input is not properly sanitized for certain commands at the CLI. An attacker could exploit this vulnerability by sending crafted commands to the CLI of an affected device. A successful exploit could allow the attacker to establish an interactive session with elevated privileges. The attacker could then use the elevated privileges to further compromise the device or obtain additional configuration data from the device.
CVSS Information
N/A
Vulnerability Type
权限、特权和访问控制
Vulnerability Title
Cisco SD-WAN Solution 权限许可和访问控制问题漏洞
Vulnerability Description
Cisco vBond Orchestrator Software等都是美国思科(Cisco)公司的产品。Cisco vBond Orchestrator Software是一套安全网络扩展管理软件。vEdge 100 Series Routers是一款100系列的路由器产品。SD-WAN Solution是运行在其中的一套网络扩展解决方案。 Cisco SD-WAN Solution 18.4.0之前版本中的本地CLI存在权限许可和访问控制漏洞,该漏洞源于程序没有正确地过滤用户输入。本地攻击者可通过发送
CVSS Information
N/A
Vulnerability Type
N/A